Configuring an IPv4 PBR Policy with a Tunnel as the Next Hop
Traffic can be configured to route over an IPsec tunnel or GRE tunnel using PBR. The following steps configure an IPsec or GRE tunnel interface as the next hop of a PBR route map.
You must configure the IPsec tunnel or GRE tunnel before configuring the traffic to route over a tunnel. For more information about IPsec tunnel configuration, refer to the Routing Traffic over an IPsec Tunnel Using PBR task. For more information about GRE tunnel configuration, refer to the RUCKUS FastIron Layer 3 Routing Configuration Guide.
- Enter the
configure terminalcommand to enter global configuration mode. - Define the required IPv4 ACLs to be added to the route map.
- Enter the
route-mapcommand to define the route and specify the match criteria and the resulting action if all the match clauses are met. - Add IPv4 ACLs to match the IP address that is permitted by the ACL.
- Set the configured tunnel as the next hop for a route map.
- Enter the
endcommand to return to global configuration mode. - Enter configuration mode on the interface where you want to enable IPv4 PBR by applying the route map.
- Enable PBR on the interface and specify the route map to be used.
The following example shows the configuration steps to route routing traffic over an IPsec tunnel using PBR.
device(config)# interface tunnel 1 device(config-tnif-1)# vrf forwarding blue device(config-tnif-1)# tunnel source ethernet 1/1/1 device(config-tnif-1)# tunnel destination 10.2.2.1 device(config-tnif-1)# tunnel mode ipsec ipv4 device(config-tnif-1)# tunnel protection ipsec profile prof-blue device(config-tnif-1)# ip address 10.4.4.4/24 device(config-tnif-1)# exit device(config)# ip access-list standard 99 device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255 device(config-std-ipacl-99)# exit device(config)# route-map test-route permit 99 device(config-routemap test-route)# match ip address 99 device(config-routemap test-route)# set next-hop-ip-tunnel 1 device(config-routemap test-route)# end device(config)# interface ethernet 1/1/3 device(config-if-e1000-1/1/3)# vrf forwarding blue device(config-if-e1000-1/1/3)# ip policy route-map test-route device(config-if-e1000-1/1/3)# end
The following example shows the configuration steps to route routing traffic over a GRE tunnel using PBR.
device(config)# interface tunnel 1 device(config-tnif-1)# vrf forwarding blue device(config-tnif-1)# tunnel source ethernet 1/1/1 device(config-tnif-1)# tunnel destination 10.2.2.1 device(config-tnif-1)# tunnel mode gre ip device(config-tnif-1)# ip address 10.4.4.4/24 device(config-tnif-1)# exit device(config)# ip access-list standard 99 device(config-std-ipacl-99)# permit 10.157.23.0 0.0.0.255 device(config-std-ipacl-99)# exit device(config)# route-map test-route permit 99 device(config-routemap test-route)# match ip address 99 device(config-routemap test-route)# set next-hop-ip-tunnel 1 device(config-routemap test-route)# end device(config)# interface ethernet 1/1/3 device(config-if-e1000-1/1/3)# vrf forwarding blue device(config-if-e1000-1/1/3)# ip policy route-map test-route device(config-if-e1000-1/1/3)# end